A regulator walked into a bank’s AI governance office and asked a simple question: “Show me your decision log for the AI systems you’re using in lending.”
The bank produced a spreadsheet: model name, version, accuracy metrics, deployment date.
The regulator asked: “Where’s the decision log? When did you decide this model’s output? When did it change? Why did you decide to use this model for this decision? Who approved it? What was the alternative?”
Blank looks.
What the bank had was a model registry. What the regulator was looking for was a decision record.
And the reason this matters is that the regulator’s job isn’t to check if your model is accurate. It’s to check if you made a reasonable decision about how to use AI in your business, and you can defend that decision.
Most enterprises aren’t prepared for that conversation. Not because they’re incompetent. But because they’ve been building technical infrastructure (governance committees, model monitoring, fairness frameworks) when they should have been building decision infrastructure.
Why Regulators Care About Decision, Not Accuracy
Here’s the shift that’s happening in regulatory thinking, and most enterprises haven’t noticed it yet:
Regulators care about what you decided to do with AI, not whether you did it well.
If you can show: “We decided to use AI in this part of our business because X. We evaluated the alternatives. We identified the risks. We have governance to manage those risks. We monitor outcomes. We’ve decided to accept these specific risks. Here’s how we track if we’re right.”
Then the regulator might actually approve. They might ask hard questions, but you have a story.
If you can’t show that—if instead you show: “We built a really good model. Look at the accuracy. Look at the fairness metrics.”—you’re not answering the question the regulator is asking.
The regulator already assumes your model is good. What they want to know is: Why did you use AI here? What problems could this cause? Have you thought about it? Who’s accountable if something goes wrong?
Most enterprises have built answer to “Is the model good?” They haven’t built an answer to “Did you decide to use AI responsibly?”
These are different questions, and they require different infrastructure.
What the Regulator is Actually Checking
When a regulator looks at your AI system, they’re asking:
Decision authority: Who decided to use AI here? Was that person qualified to make this decision? Did they understand the risks?
Alternatives considered: Did you evaluate other ways to solve this problem? Why did you choose AI? Why not just use rules? Why not keep the human in the loop?
Risk assessment: Did you identify what could go wrong? Have you thought about fairness, accuracy, security, operational risk? Or did you just think “this model is accurate”?
Monitoring and accountability: How will you know if something goes wrong? Who’s accountable? Do you have a way to fix it if you need to?
Documented reasoning: Can you show me the decision? Not the model performance. The decision about whether to use the model.
Most enterprises would fail this audit today. Not because your models aren’t good. But because you can’t show the decision.
You have model cards. You don’t have decision records.
What You Actually Need to Build
Here’s what “decision infrastructure” looks like:
Decision record template. Before you deploy an AI system, someone fills this out: What decision are we using AI to make? What are the alternatives? Why are we choosing AI? What could go wrong? What’s our monitoring plan? Who’s accountable?
This is boring and unsexy. Nobody gets excited about decision records. But when a regulator asks “how did you decide to use AI here?” you can point to a document that answers the question.
Audit trail. When you change a model, when you change monitoring, when you escalate a risk, you should have a record. Not “we deployed version 2 on this date.” But “we decided to change the monitoring thresholds because X, here’s who approved it, here’s the reasoning.”
This isn’t new. Banks have done this for lending decisions for decades. The infrastructure exists. Most enterprises just haven’t applied it to AI systems.
Escalation record. When something goes wrong with the AI system (accuracy drops, outcomes drift, fairness metric breaks), do you have a record of what happened and what you decided to do? That’s what regulators care about. Not that nothing went wrong. But that you caught it and did something about it.
Most enterprises have an incident response plan. They don’t have a “what did we decide when we found a problem with the AI system” plan.
Approval authority. When you want to deploy an AI system or make a material change to one, who approves it? Not a committee. A person. With clear authority. Who will own the decision if something goes wrong.
The Conversation Regulators Are Having
Regulators are starting to enforce this. It’s not consistent yet (different regulators care about different things), but the pattern is becoming clear:
“You have to be able to explain your AI decisions.”
This is not “you have to have a fair model.” This is “you have to be able to explain why you decided to use a model, what you evaluated, and what you’re doing to make sure it works.”
Some regulators care more about fairness. Some care more about security. Some care about operational risk. But all of them care about the decision.
And they’re discovering what I’ve seen in every enterprise: most companies can’t explain the decision. They can explain the model. The model is great. But the decision to use the model in the business? That decision was never explicitly made.
What This Means for Your Enterprise Now
If you’re waiting for regulatory guidance to clarify what they want, you’re late. Regulators are starting to conduct reviews now, and they’re finding the infrastructure gap.
What you should do:
-
Start with one model. Pick a model that’s already deployed. Walk through the decision. Who decided to use it? Did they document their reasoning? Do you have an alternatives analysis?
-
Build the decision record backward. You don’t have to have perfect decisions. But you have to be able to explain them. When a regulator asks “why did you use AI here?” you should be able to answer in a sentence or two.
-
Set up escalation tracking. When something changes with the model—accuracy drops, fairness metrics break, operational impact—do you have a record of what you discovered and what you decided to do?
-
Identify your approval authority. This is a person, not a committee. They can consult the committee. But they own the decision.
-
Plan for the hard conversations. When a regulator asks “can you defend this decision?” you might realize you can’t. That’s okay. You’re learning. But it’s better to learn this before a formal review.
The Difference Between Compliance Theater and Actual Compliance
Here’s the trap: you can build all the governance theater in the world—committees, frameworks, monitoring—and still not be able to answer a regulator’s actual questions.
Real compliance means: when a regulator asks “did you think about this?” you can say “yes, here’s what we thought, here’s what we decided, here’s how we’re managing it.”
Theater means: when a regulator asks “did you think about this?” you produce a document that says “we have governance” but doesn’t show that you actually thought about anything.
The companies that are handling this well are building decision infrastructure, not governance infrastructure. They’re keeping records of decisions. They’re being explicit about who decided what. They’re documenting their reasoning.
It’s not impressive. It’s not technically sophisticated. It’s boring process work.
But when a regulator asks for it, you have it. And that’s the difference between a review that goes smoothly and one that doesn’t.
The Regulatory Reckoning
There’s a regulatory reckoning coming. Not because regulators are anti-AI. But because regulators are starting to apply the same bar to AI systems that they apply to everything else: Can you defend the decision?
Most enterprises would fail that bar right now.
The time to fix this is now, not when you’re in a regulatory review. Build the decision infrastructure. Document your thinking. Make explicit decisions with clear authority.
Because when a regulator asks “show me your decision log,” you’re going to want to have one.